cgiscript.net
http://www.cgiscript.net/cgi-script/csNews/csNews.cgi?database=cgi.db&command=viewone&id=7 CVE-2002-0495
CSSearch 2.3 - Remote Command Execution
Record summary
CVE-2002-0495 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCSSearch 2.3 - Remote Command ExecutionExploitDB exploitby Steve GustinNot analyzed1 file
References
5cssearch-url-execute-commands(8636)vdb entry
http://www.iss.net/security_center/static/8636.php 20020325 CGIscript.net - csSearch.cgi - Remote Code Execution (up to 17,000 sites vulnerable)mailing list
http://www.securityfocus.com/archive/1/264169 4368vdb entry
http://www.securityfocus.com/bid/4368 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0495